Back to LiftPlanProUK
UK GDPR processor terms

Data Processing Agreement

Effective 18 August 2026
Controller–processor terms

This Agreement applies where LiftPlan processes personal data contained in Customer content on behalf of a business Customer.

1. Status and incorporation

This Data Processing Agreement (DPA) forms part of the Terms & Conditions between the Customer and Billinge Diving and Marine Services Ltd (Provider) where the Provider processes Customer Personal Data as processor.

The Customer is the controller and the Provider is the processor for Customer Personal Data. Each party must comply with the UK GDPR, the Data Protection Act 2018 and other applicable UK data-protection law. This DPA does not apply where the Provider acts as controller for its own account, billing, security, legal or business-administration data, which is covered by the Privacy Notice.

2. Definitions

Customer Personal Data means personal data submitted to, stored in or generated through the Service by or for the Customer and processed by the Provider on the Customer's behalf. Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in applicable data-protection law.

3. Processing instructions

The Provider will process Customer Personal Data only:

  • to host, organise, calculate, display, export, share, secure, back up and support Customer lift-plan content and related workflows;
  • as necessary to provide the Service and purchased support or verification services;
  • on documented instructions contained in the Terms, the Customer's configuration and use of the Service, and authorised support requests; or
  • where required by law, in which case the Provider will inform the Customer before processing unless legally prohibited.

If the Provider reasonably believes an instruction infringes data-protection law, it will notify the Customer and may suspend the affected processing until the issue is resolved.

4. Customer responsibilities

The Customer must:

  • have an appropriate lawful basis and provide required privacy information to personnel and other data subjects;
  • ensure its instructions and use of the Service comply with law;
  • limit data to what is relevant and necessary, keep it accurate, and avoid special-category or criminal-offence data unless specifically necessary and lawful;
  • configure access appropriately, protect credentials and remove access promptly when no longer authorised; and
  • respond to data-subject requests and determine retention and deletion requirements for its controlled project records.

5. Confidentiality and personnel

The Provider will ensure that persons authorised to process Customer Personal Data are subject to confidentiality obligations, receive appropriate instructions and access the data only to the extent necessary for their role.

6. Security measures

Taking account of the nature, scope, context and risk of the processing, the Provider will maintain proportionate technical and organisational measures, including as appropriate:

  • authenticated accounts, role-based and restricted administrative access;
  • password hashing, secure session-cookie settings and encrypted network transmission;
  • segregated customer access controls and controlled storage permissions;
  • logging, monitoring, backup and recovery arrangements appropriate to the Service;
  • payment-card processing through Stripe rather than storage of full card details by LiftPlan;
  • vulnerability, incident and supplier-management procedures; and
  • periodic review of access, data minimisation and security controls.

The Customer acknowledges that security measures may develop as technology and risks change, provided that the overall protection is not materially reduced.

7. Subprocessors

The Customer gives general written authorisation for the Provider to appoint subprocessors needed to operate the Service. These currently include Floot and infrastructure providers engaged through Floot for application hosting, server functions, databases, file storage, security and service communications.

The Provider will require each subprocessor to protect Customer Personal Data under written terms providing materially equivalent data-protection obligations. The Provider remains responsible for its subprocessor's performance to the extent required by law.

The Provider will give reasonable notice of a material new subprocessor where practicable. The Customer may object within 14 days on reasonable data-protection grounds. The parties will work in good faith to resolve the objection; if no reasonable alternative is available, either party may end the affected Service without affecting fees already due for services supplied.

Stripe processes payment information separately and may act as an independent controller for parts of its payment and fraud-prevention processing.

8. International transfers

The Provider will not transfer Customer Personal Data outside the United Kingdom unless permitted by applicable law. Where a restricted transfer occurs, the Provider will use an adequacy arrangement or appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum, and will carry out any transfer assessment and supplementary measures reasonably required.

9. Assistance

Taking account of the nature of processing and information available, the Provider will provide reasonable assistance with:

  • data-subject access, correction, deletion, restriction, portability and objection requests;
  • security obligations and personal data breach assessment and notification;
  • data-protection impact assessments and prior consultation where the Customer's use is likely to result in high risk; and
  • demonstrating the Customer's compliance with applicable processor requirements.

The Provider may charge reasonable costs for substantial assistance outside normal Service functionality where the need was not caused by the Provider's breach.

10. Personal data breaches

The Provider will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include available information about the nature of the breach, likely consequences, affected data and subjects, mitigation and a contact point. Information may be provided in stages where it is not immediately available.

The Customer remains responsible for deciding whether and how to notify the ICO, other authorities or affected individuals in its role as controller.

11. Return and deletion

During an active account, the Customer should export and retain the controlled records it requires. At the end of the relevant Service, the Provider will, at the Customer's choice and subject to available Service functionality, return or delete Customer Personal Data unless law requires continued storage.

Deletion from live systems may not immediately remove data from protected backups. Backup copies will remain isolated from routine use and be deleted or overwritten through the normal backup cycle, unless restoration is required for security or continuity.

12. Information and audits

The Provider will make available information reasonably necessary to demonstrate compliance with this DPA. Audits should normally begin with current policies, security summaries, certificates or written responses. If further audit is reasonably required, it must be arranged on reasonable notice, during business hours, no more than once annually unless a breach or regulator requires otherwise, and without compromising other customers, security or confidential information.

The Customer bears its audit costs and the Provider's reasonable assistance costs unless the audit identifies a material Provider breach.

13. Processing details

Subject matter and purpose: provision of LiftPlan's hosted lift-planning, document, approval, verification, account-support and related functionality.

Duration: for the term of the Customer's account or purchased Service and the limited retention or backup period described in this DPA and the Privacy Notice.

Nature of processing: collection, recording, organisation, calculation, structuring, storage, retrieval, consultation, display, transmission at the Customer's direction, export, restriction, backup and deletion.

Data subjects: Customer Users, employees, contractors, Appointed Persons, operators, lift supervisors, slinger/signallers, managers, reviewers and other people identified in Customer project records.

Data categories: names, business contact information, employers and roles, permissions, qualifications and card details, expiry dates, electronic or drawn signatures, project and site information, lift-plan entries, uploaded documents, approval and workflow records, and related audit metadata.

Special-category data: not intentionally required. The Customer must not provide it unless necessary, lawful and appropriately protected.

14. Order of precedence and law

If this DPA conflicts with the Terms on the protection of Customer Personal Data, this DPA prevails. Otherwise, the Terms, including liability provisions, continue to apply. This DPA is governed by the law of England and Wales and the courts of England and Wales have exclusive jurisdiction, subject to mandatory law.

Questions and data-protection instructions should be sent to info@LiftPlanProUK.com.